Dear KM:
This is 3rd DrtWatson Logog file.
refer below
<DrtWatson Log 3>
ì‘ìš© 프로그램 예외 ë°œìƒ:
ì‘ìš© 프로그램: C:\WINDOWS\system32\rundll32.exe (pid=1748)
ë‚ ì§œ: 2004-08-25 @ 07:45:07.067
예외 번호: c0000094 (0으로 나눔)
*----> 시스템 ì •ë³´ <----*
컴퓨터 ì´ë¦„: OEM-GGPLF1VIE8M
ì‚¬ìš©ìž ì´ë¦„: SYSTEM
í„°ë¯¸ë„ ì„œë¹„ìŠ¤ 세션 Id: 0
프로세서 수: 1
프로세서 ìœ í˜•: x86 Family 6 Model 9 Stepping 8
Windows ë²„ì „: 5.1
현재 빌드: 2600
Service Pack: 1
현재 ìœ í˜•: Uniprocessor Free
등ë¡ëœ ì¡°ì§: OEM
등ë¡ëœ ì†Œìœ ìž: OEM
*----> 작업 ëª©ë¡ <----*
0 System Process
4 System
680 smss.exe
752 csrss.exe
776 winlogon.exe
824 services.exe
832 lsass.exe
984 svchost.exe
1084 svchost.exe
1228 svchost.exe
1240 svchost.exe
1248 Explorer.exe
1424 spoolsv.exe
1488 VTTimer.exe
1496 VTtrayp.exe
1748 rundll32.exe
1820 DUAgent.exe
1844 inetinfo.exe
1896 SCardSvr.exe
1984 snmp.exe
1512 drwtsn32.exe
*----> 모듈 ëª©ë¡ <----*
(0000000000960000 - 000000000098b000: C:\WINDOWS\System32\msctfime.ime
(0000000000de0000 - 0000000000de4000: C:\WINDOWS\System32\EmbdTrst.DLL
(0000000001000000 - 000000000100a000: C:\WINDOWS\system32\rundll32.exe
(0000000010000000 - 0000000010036000: C:\WINDOWS\system32\VTRfLock.dll
(000000003a700000 - 000000003a718000: C:\WINDOWS\System32\imekr61.ime
(00000000559e0000 - 0000000055a51000: C:\WINDOWS\system32\themeui.dll
(0000000058ab0000 - 0000000058ad4000: C:\WINDOWS\System32\desk.cpl
(000000005ad70000 - 000000005ada4000: C:\WINDOWS\system32\UxTheme.dll
(00000000629c0000 - 00000000629c8000: C:\WINDOWS\system32\LPK.DLL
(000000006b980000 - 000000006b9ca000: C:\WINDOWS\system32\VTCfg3d.dll
(000000006bb00000 - 000000006bb73000: C:\WINDOWS\system32\VTDisply.dll
(000000006be00000 - 000000006be57000: C:\WINDOWS\system32\VTGamma2.dll
(000000006c000000 - 000000006c03a000: C:\WINDOWS\system32\VTInfo2.dll
(000000006c200000 - 000000006c258000: C:\WINDOWS\system32\VTOvrlay.dll
(000000006c400000 - 000000006c4c2000: C:\WINDOWS\system32\VTChromo.dll
(000000006d3f0000 - 000000006d3f7000: C:\WINDOWS\system32\deskperf.dll
(000000006d400000 - 000000006d407000: C:\WINDOWS\system32\deskmon.dll
(000000006d410000 - 000000006d417000: C:\WINDOWS\system32\deskadp.dll
(0000000070a70000 - 0000000070ad5000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000071950000 - 0000000071a34000:
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
(0000000072fa0000 - 0000000072ffa000: C:\WINDOWS\system32\USP10.dll
(0000000074770000 - 00000000747ff000: C:\WINDOWS\system32\MLANG.dll
(0000000075150000 - 0000000075163000: C:\WINDOWS\system32\Cabinet.dll
(0000000075f40000 - 0000000075f5f000: C:\WINDOWS\system32\apphelp.dll
(0000000076380000 - 0000000076385000: C:\WINDOWS\system32\MSIMG32.dll
(0000000076390000 - 00000000763ac000: C:\WINDOWS\System32\IMM32.DLL
(0000000076670000 - 0000000076757000: C:\WINDOWS\system32\SETUPAPI.dll
(0000000076b40000 - 0000000076b6c000: C:\WINDOWS\system32\WINMM.dll
(0000000076c90000 - 0000000076cb2000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076f90000 - 0000000076fa0000: C:\WINDOWS\system32\Secur32.dll
(0000000077050000 - 0000000077115000: C:\WINDOWS\system32\COMRes.dll
(0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000771b0000 - 00000000772d4000: C:\WINDOWS\System32\ole32.dll
(0000000077340000 - 00000000773cb000: C:\WINDOWS\system32\comctl32.dll
(00000000773d0000 - 0000000077bc2000: C:\WINDOWS\system32\shell32.dll
(0000000077c00000 - 0000000077c07000: C:\WINDOWS\system32\VERSION.dll
(0000000077c10000 - 0000000077c63000: C:\WINDOWS\system32\msvcrt.dll
(0000000077d40000 - 0000000077dcc000: C:\WINDOWS\system32\USER32.dll
(0000000077dd0000 - 0000000077e5d000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e60000 - 0000000077f46000: C:\WINDOWS\system32\kernel32.dll
(0000000077f50000 - 0000000077ff7000: C:\WINDOWS\System32\ntdll.dll
(0000000078000000 - 0000000078087000: C:\WINDOWS\system32\RPCRT4.dll
(000000007c890000 - 000000007c911000: C:\WINDOWS\system32\CLBCATQ.DLL
(000000007e090000 - 000000007e0d1000: C:\WINDOWS\system32\GDI32.dll
*----> ìŠ¤ë ˆë“œ Id 0x6d8ì˜ ìƒíƒœ ë¤í”„ <----*
eax=0002b110 ebx=1d0a0279 ecx=00000000 edx=00000000 esi=00010136 edi=00000000
eip=6c005592 esp=0006da54 ebp=0006dc4c iopl=0 nv up ei pl nz ac po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000216
*** WARNING: Unable to verify checksum for C:\WINDOWS\system32\VTInfo2.dll
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\VTInfo2.dll -
함수: VTInfo2!Ordinal4
6c005579 45 inc ebp
6c00557a 1499 adc al,0x99
6c00557c f7ff idiv edi
6c00557e 57 push edi
6c00557f 8b7d1c mov edi,[ebp+0x1c]
6c005582 897ddc mov [ebp-0x24],edi
6c005585 8945c8 mov [ebp-0x38],eax
6c005588 8b45b8 mov eax,[ebp-0x48]
6c00558b 69c090010000 imul eax,eax,0x190
6c005591 99 cdq
오류 -> 6c005592 f7f9 idiv ecx
6c005594 0fafc1 imul eax,ecx
6c005597 99 cdq
6c005598 59 pop ecx
6c005599 f7f9 idiv ecx
6c00559b 8b8d40ffffff mov ecx,[ebp-0xc0]
6c0055a1 6a10 push 0x10
6c0055a3 894dd8 mov [ebp-0x28],ecx
6c0055a6 8945d0 mov [ebp-0x30],eax
6c0055a9 8b8578ffffff mov eax,[ebp-0x88]
6c0055af 0faf4518 imul eax,[ebp+0x18]
*----> ìŠ¤íƒ ì— ì¶”ì <----*
WARNING: Stack unwind information not available. Following frames may be
wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\USER32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\themeui.dll -
ChildEBP RetAddr Args to Child
0006dc4c 6c00f52f 00010136 1d0a0279 00000000 VTInfo2!Ordinal4+0x5592
0006dc70 77d43a50 00010136 00000601 00000000 VTInfo2+0xf52f
0006dc9c 77d4c675 6c00f35a 00010136 00000601 USER32+0x3a50
0006dd08 77d4c4e4 00000000 6c00f35a 00010136 USER32!CharLowerBuffA+0x404
0006dd50 77d4c6d1 00000000 00000601 00000000 USER32!CharLowerBuffA+0x273
0006dd94 77d43b1f 77d4c6b0 00010136 00000601 USER32!DefDlgProcA+0x21
0006ddfc 77d43d79 00000000 77d4c6b0 00010136 USER32+0x3b1f
0006de5c 77d43ddf 0006dec4 00000000 77d4b1f5 USER32!GetMessageW+0x125
0006de8c 71964add 00010110 004d65d0 00086808 USER32!DispatchMessageW+0xb
0006dea8 71966b69 000b9e20 0006dec4 000b9f44 comctl32!Ordinal164+0xafb
0006df00 71966d4d 000100ac 0000016c 00000000 comctl32!Ordinal164+0x2b87
0006df58 55a0428b 0006e604 00000111 00091ef0 comctl32!Ordinal164+0x2d6b
0006e5fc 00000800 00000034 00000101 000100ac themeui+0x2428b
*----> 로 ìŠ¤íƒ ë¤í”„ <----*
000000000006da54 64 00 00 00 e4 dc 06 00 - 00 00 00 00 00 00 00 00
d...............
000000000006da64 f4 ff ff ff 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000006da74 90 01 00 00 00 00 00 a2 - 00 00 00 00 b1 bc b8 b2
.................
000000000006da84 00 00 00 00 c6 40 d4 77 - 88 db 06 00 b3 5f 96 71
[email protected]....._.q
000000000006da94 00 00 00 00 8c da 06 00 - 1c dc 06 00 f4 ff ff ff
.................
000000000006daa4 00 00 00 00 00 00 00 00 - 00 00 00 00 90 01 00 00
.................
000000000006dab4 00 00 00 a2 00 00 00 00 - b1 bc b8 b2 00 db 06 00
.................
000000000006dac4 b3 5f 96 71 00 00 00 00 - 91 c6 d4 77 4e 00 00 00
.._.q.......wN...
000000000006dad4 10 01 01 00 40 54 4d 00 - f5 ff ff ff 00 00 00 00
.....@TM.........
000000000006dae4 00 00 00 00 00 00 00 00 - 90 01 00 00 00 00 00 81
.................
000000000006daf4 00 00 00 00 4d 53 20 53 - 68 65 6c 6c 20 44 6c 67 ....MS
Shell Dlg
000000000006db04 00 00 00 00 d0 da 06 00 - 3d 00 00 00 ec dd 06 00
.........=.......
000000000006db14 40 db 06 00 0d 00 00 00 - 0b 00 00 00 02 00 00 00
@...............
000000000006db24 02 00 00 00 00 00 00 00 - 06 00 00 00 15 00 00 00
.................
000000000006db34 bc 02 00 00 00 00 00 00 - 60 00 00 00 60 00 00 00
.........`...`...
000000000006db44 1e ff 1f 20 00 00 00 27 - 81 db 06 00 f5 ff ff ff ...
....'........
000000000006db54 00 00 00 00 00 00 00 00 - 00 00 00 00 bc 02 00 00
.................
000000000006db64 00 00 00 81 00 00 00 00 - 4d 53 20 53 68 65 6c 6c
.........MS Shell
000000000006db74 20 44 6c 67 00 00 00 00 - f8 d5 08 00 d0 62 08 00
Dlg.........b..
000000000006db84 00 00 00 00 00 00 00 00 - 0c 00 00 00 0a 00 00 00
.................
*----> ìŠ¤ë ˆë“œ Id 0x6e0ì˜ ìƒíƒœ ë¤í”„ <----*
eax=77f883de ebx=00000000 ecx=77f53870 edx=00000000 esi=0006be40 edi=0006be3c
eip=7ffe0306 esp=00c6ff9c ebp=00c6ffb4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
함수: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8d542408 lea edx,[esp+0x8]
7ffe0304 cd2e int 2e
7ffe0306 c3 ret
7ffe0307 8bd4 mov edx,esp
7ffe0309 0f34 sysenter
7ffe030b c3 ret
7ffe030c 9c pushfd
7ffe030d 810c2400010000 or dword ptr [esp],0x100
7ffe0314 9d popfd
7ffe0315 c3 ret
7ffe0316 8bd4 mov edx,esp
7ffe0318 0f05 syscall
7ffe031a c3 ret
*----> ìŠ¤íƒ ì— ì¶”ì <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\System32\ntdll.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\kernel32.dll -
WARNING: Stack unwind information not available. Following frames may be
wrong.
ChildEBP RetAddr Args to Child
00c6ff98 77f5b7f4 77f88423 00000001 00c6ffac *SharedUserSystemCall+0xe (FPO:
[0,0,0])
00c6ffb4 77e7d33b 00000000 0006be3c 0006be40 ntdll!ZwDelayExecution+0xc
00c6ffec 00000000 77f883de 00000000 00000000
kernel32!RegisterWaitForInputIdle+0x43
*----> 로 ìŠ¤íƒ ë¤í”„ <----*
0000000000c6ff9c f4 b7 f5 77 23 84 f8 77 - 01 00 00 00 ac ff c6 00
....w#..w........
0000000000c6ffac 00 00 00 00 00 00 00 80 - ec ff c6 00 3b d3 e7 77
.............;..w
0000000000c6ffbc 00 00 00 00 3c be 06 00 - 40 be 06 00 00 00 00 00
.....<...@.......
0000000000c6ffcc 00 00 00 00 00 d0 fd 7f - c0 ff c6 00 07 00 00 00
.................
0000000000c6ffdc ff ff ff ff 09 48 e9 77 - b8 3d e8 77 00 00 00 00
......H.w.=.w....
0000000000c6ffec 00 00 00 00 00 00 00 00 - de 83 f8 77 00 00 00 00
............w....
0000000000c6fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c7000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c7001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c7002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c7003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c7004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c7005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c7006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c7007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c7008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c7009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c700ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c700bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c700cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
*----> ìŠ¤ë ˆë“œ Id 0x6e4ì˜ ìƒíƒœ ë¤í”„ <----*
eax=00000000 ebx=00000000 ecx=77f59037 edx=00000000 esi=77fc59a0 edi=77fc59fc
eip=7ffe0306 esp=00caff70 ebp=00caffb4 iopl=0 nv up ei ng nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000286
함수: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8d542408 lea edx,[esp+0x8]
7ffe0304 cd2e int 2e
7ffe0306 c3 ret
7ffe0307 8bd4 mov edx,esp
7ffe0309 0f34 sysenter
7ffe030b c3 ret
7ffe030c 9c pushfd
7ffe030d 810c2400010000 or dword ptr [esp],0x100
7ffe0314 9d popfd
7ffe0315 c3 ret
7ffe0316 8bd4 mov edx,esp
7ffe0318 0f05 syscall
7ffe031a c3 ret
*----> ìŠ¤íƒ ì— ì¶”ì <----*
WARNING: Stack unwind information not available. Following frames may be
wrong.
ChildEBP RetAddr Args to Child
00caff6c 77f5c024 77f95b41 00000148 00caffac *SharedUserSystemCall+0xe (FPO:
[0,0,0])
00caffb4 77e7d33b 00000000 0006bed0 00080000 ntdll!ZwRemoveIoCompletion+0xc
00caffec 00000000 77f95b06 00000000 00000000
kernel32!RegisterWaitForInputIdle+0x43
*----> 로 ìŠ¤íƒ ë¤í”„ <----*
0000000000caff70 24 c0 f5 77 41 5b f9 77 - 48 01 00 00 ac ff ca 00
$..wA[.wH.......
0000000000caff80 b0 ff ca 00 98 ff ca 00 - a0 ff ca 00 d0 be 06 00
.................
0000000000caff90 00 00 08 00 00 00 00 00 - 00 00 00 00 88 6a 09 00
..............j..
0000000000caffa0 00 7c 28 e8 ff ff ff ff - a4 8c 3b f5 26 61 f9 77
..|(.......;.&a.w
0000000000caffb0 a0 6a 09 00 ec ff ca 00 - 3b d3 e7 77 00 00 00 00
..j......;..w....
0000000000caffc0 d0 be 06 00 00 00 08 00 - 00 00 00 00 00 00 00 00
.................
0000000000caffd0 00 c0 fd 7f c0 ff ca 00 - 07 00 00 00 ff ff ff ff
.................
0000000000caffe0 09 48 e9 77 b8 3d e8 77 - 00 00 00 00 00 00 00 00
..H.w.=.w........
0000000000cafff0 00 00 00 00 06 5b f9 77 - 00 00 00 00 00 00 00 00
......[.w........
0000000000cb0000 00 00 00 00 9f 00 13 00 - 10 00 90 01 17 00 b0 01
.................
0000000000cb0010 ff ff ff 00 ff ff ff 00 - 00 00 00 00 00 00 00 00
.................
0000000000cb0020 ff ff ff 00 ff ff ff 00 - 00 00 00 00 00 00 00 00
.................
0000000000cb0030 00 00 00 00 01 00 00 00 - 0d 02 01 01 00 00 00 00
.................
0000000000cb0040 00 00 00 00 00 00 00 00 - 00 00 00 00 02 00 00 00
.................
0000000000cb0050 01 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000cb0060 00 00 00 00 1f 00 89 01 - 00 00 00 00 ff ff ff ff
.................
0000000000cb0070 ff ff ff ff 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000cb0080 00 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000cb0090 23 00 8a 01 00 00 00 40 - 06 00 00 00 00 00 00 00
#......@........
0000000000cb00a0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 40
................@